Open navigation menu
Close suggestions
Search
Search
en
Change Language
Upload
Sign in
Sign in
Download free for days
0 ratings
0% found this document useful (0 votes)
27 views
1 page
VMware Cloud On AWS Security VPC Ra
VMware Cloud on AWS – Security VPC Reference Architecture
Uploaded by
marsmaggot
AI-enhanced title
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here
.
Available Formats
Download as PDF, TXT or read online on Scribd
Download now
Download
Save VMware-cloud-on-AWS-security-VPC-ra For Later
Download
Save
Save VMware-cloud-on-AWS-security-VPC-ra For Later
0%
0% found this document useful, undefined
0%
, undefined
Embed
Share
Print
Report
0 ratings
0% found this document useful (0 votes)
27 views
1 page
VMware Cloud On AWS Security VPC Ra
VMware Cloud on AWS – Security VPC Reference Architecture
Uploaded by
marsmaggot
AI-enhanced title
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content,
claim it here
.
Available Formats
Download as PDF, TXT or read online on Scribd
Download now
Download
Save VMware-cloud-on-AWS-security-VPC-ra For Later
Carousel Previous
Carousel Next
Download
Save
Save VMware-cloud-on-AWS-security-VPC-ra For Later
0%
0% found this document useful, undefined
0%
, undefined
Embed
Share
Print
Report
Download now
Download
You are on page 1
/ 1
Search
Fullscreen
VMware Cloud on AWS – Security VPC Reference Architecture 1 Deploy a software-defined data center (SDDC) into
an SDDC group. This automatically builds a
Integrate third-party firewall appliances into VMware Cloud on AWS by leveraging the VMware Transit Connect. VMware-managed Transit Gateway (VTGW) and
establishes connectivity between SDDCs via the
VTGW.
Internet Destination Target
Build a security virtual private cloud (VPC) with
Destination Target 2
SecVPC-CIDR local access to the internet via an internet gateway (IGW).
VMware Cloud on AWS SecVPC-CIDR local VPC-ALL-CIDR Transit Gateway
Create one public subnet with access to the IGW
- SDDC Group 0.0.0.0/0 IGW OnPrem-CIDR Transit Gateway
3 and connect it to the firewall internet-bound elastic
Internet
Gateway network interface (ENI). Network interface (Eth1/3)
0.0.0.0/0 FW-ENI-Eth1/1
VMware Cloud on AWS is assigned to an internet security zone (also called
2 zone “Internet”) within the firewall appliance.
- SDDC01 Security VPC Amazon VPC
On-Premises
(Workload VPC01) Provision one private subnet that will be attached
Data Center
4 to the VTGW, with a dedicated route table to
subnet-03 3 push all SDDC outbound traffic to the firewall
Zone-Internet interface (Eth1/2), which is assigned to a security
zone for the SDDC group (Zone “SDDC”).
1
Deploy another private subnet with a separate
Eth-1/3 5 5 route table to be attached to the customer
subnet-02 subnet-01 managed AWS Transit Gateway and the firewall
8 Eth-1/2 Eth-1/1 7 Direct AWS Direct
interface (Eth1/1), which is assigned to a separate
security zone for the AWS native side (Zone “AWS”).
VMware Transit AWS Transit Gateway Connect Connect
Connect (VMware
Zone-SDDC Zone-AWS Gateway Provision a third-party (zone-based) firewall
VMware Cloud on AWS 6 (Customer managed) 6
managed Transit appliance within the Security VPC to provide
- SDDC02 Firewall Appliance
Gateway) 4 transitive routing and policy inspection from zone
SDDC to zone AWS and the Internet zone.
Amazon VPC
“Source/Destination Check” must be disabled on all
(Workload VPC02) ENIs attached to the firewall. For internet access,
source network address translation (SNAT) must be
Destination Target Destination Target configured on firewall appliance to maintain route
VPC01-CIDR tgw-vpc01-attachment
symmetry.
VPC-ALL-CIDR Eth1/1
Destination Target Destination Target VPC02-CIDR tgw-vpc02-attachment Create a new (or attach the existing) customer-
OnPrem-CIDR Eth1/1 7 managed AWS Transit Gateway to the Security VPC
SDDC01-CIDR vtgw-sddc01-attachment SecVPC-CIDR local SDDC-ALL-CIDR Eth1/2 OnPrem-CIDR DXGW using subnet-01. This provides transitive routing
SDDC02-CIDR vtgw-sddc02-attachment SDDC-ALL-CIDR VTGW between SDDCs and existing workload VPCs and on-
0.0.0.0/0 Eth1/3 SDDC-ALL-CIDR tgw-secvpc-attachment
premises data centers.
0.0.0.0/0 vtgw-secvpc-attachment 0.0.0.0/0 FW-ENI-Eth1/2 0.0.0.0/0 tgw-secvpc-attachment
Attach the Security VPC to the VTGW using subnet-
(Optional) 8 02. Configure a static default route at the VTGW
towards the Security VPC attachment. All SDDC
outbound traffic to the internet, and inbound access
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved. from the internet will be enforced to go through the
firewall appliance within the Security VPC.
You might also like
AWS - VPC Notes
PDF
No ratings yet
AWS - VPC Notes
9 pages
Medicine Rapid Revision 2 Only@latestpgnotes PDF
PDF
No ratings yet
Medicine Rapid Revision 2 Only@latestpgnotes PDF
158 pages
Book Review:: M. L. Liu Addison-Wesley, 2004 ISBN 0-201-79644-9
PDF
No ratings yet
Book Review:: M. L. Liu Addison-Wesley, 2004 ISBN 0-201-79644-9
1 page
Vmware Cloud On Aws Networking Ra
PDF
No ratings yet
Vmware Cloud On Aws Networking Ra
4 pages
Enterprise Networking and SD-Wan With Cisco and AWS
PDF
No ratings yet
Enterprise Networking and SD-Wan With Cisco and AWS
35 pages
VPC by Cloud MadeEasy
PDF
No ratings yet
VPC by Cloud MadeEasy
5 pages
Vmware Cloud On Aws Networking Ra
PDF
No ratings yet
Vmware Cloud On Aws Networking Ra
4 pages
SD Wan Deployment Models Ra
PDF
No ratings yet
SD Wan Deployment Models Ra
5 pages
M06 - SecSpl - NetworkingSecurity 1
PDF
No ratings yet
M06 - SecSpl - NetworkingSecurity 1
55 pages
vpc
PDF
No ratings yet
vpc
1 page
AwsNetworkingInterviewQuestions
PDF
No ratings yet
AwsNetworkingInterviewQuestions
10 pages
Traffic Encryption Options Direct Connect Ra
PDF
No ratings yet
Traffic Encryption Options Direct Connect Ra
5 pages
Vmware Cloud On Aws Cloud Wan Ra
PDF
No ratings yet
Vmware Cloud On Aws Cloud Wan Ra
1 page
Get The Most, From The Best!!
PDF
No ratings yet
Get The Most, From The Best!!
48 pages
Traffic Encryption Options Direct Connect Ra
PDF
No ratings yet
Traffic Encryption Options Direct Connect Ra
5 pages
VPC Dark
PDF
No ratings yet
VPC Dark
1 page
4-Networking & Content Delivery_241022_203735
PDF
No ratings yet
4-Networking & Content Delivery_241022_203735
88 pages
1.1 VPC - Course - Slides
PDF
No ratings yet
1.1 VPC - Course - Slides
89 pages
Ex. 11 -Configure a VPC
PDF
No ratings yet
Ex. 11 -Configure a VPC
3 pages
GIU_2724_62_15996_2024-02-19T17_40_13 (1)
PDF
No ratings yet
GIU_2724_62_15996_2024-02-19T17_40_13 (1)
41 pages
Comprehensive Guide to AWS Virtual Private Cloud (VPC)
PDF
No ratings yet
Comprehensive Guide to AWS Virtual Private Cloud (VPC)
19 pages
VPC-Document
PDF
No ratings yet
VPC-Document
13 pages
AWS 2-03 Networking in the AWS Cloud
PDF
No ratings yet
AWS 2-03 Networking in the AWS Cloud
31 pages
Building A Scalable and Secure Multi-VPC AWS Network Infrastructure
PDF
No ratings yet
Building A Scalable and Secure Multi-VPC AWS Network Infrastructure
45 pages
VPC New
PDF
No ratings yet
VPC New
36 pages
Extra Networking Lab 1 Multi-VPC Account Architecture
PDF
No ratings yet
Extra Networking Lab 1 Multi-VPC Account Architecture
26 pages
Cheat Sheets - 2
PDF
No ratings yet
Cheat Sheets - 2
10 pages
Networking in AWS
PDF
No ratings yet
Networking in AWS
32 pages
VMware Cloud On AWS Networking and Security
PDF
No ratings yet
VMware Cloud On AWS Networking and Security
142 pages
VPC (VIRTUAL PRIVATE CLOUD)
PDF
No ratings yet
VPC (VIRTUAL PRIVATE CLOUD)
59 pages
Week 6 - Webinar
PDF
No ratings yet
Week 6 - Webinar
26 pages
GIU_2724_62_15996_2024-02-19T17_40_13 (1)
PDF
No ratings yet
GIU_2724_62_15996_2024-02-19T17_40_13 (1)
41 pages
Networking in AWS - Part 1
PDF
No ratings yet
Networking in AWS - Part 1
39 pages
Aws Application Load Balancer Integration VMC Aws Reference Architecture
PDF
100% (1)
Aws Application Load Balancer Integration VMC Aws Reference Architecture
1 page
Lab Network AWS - Ali Zaenal a.A
PDF
No ratings yet
Lab Network AWS - Ali Zaenal a.A
28 pages
Amazon Virtual Private Cloud - Lab
PDF
No ratings yet
Amazon Virtual Private Cloud - Lab
15 pages
AWS-VPC
PDF
No ratings yet
AWS-VPC
53 pages
Hybrid Connectivity To Transit Gateway Ra
PDF
No ratings yet
Hybrid Connectivity To Transit Gateway Ra
9 pages
VPC Design and New Capabilitie 1729106471 180510173437
PDF
No ratings yet
VPC Design and New Capabilitie 1729106471 180510173437
74 pages
ID Partner Network Transformation
PDF
No ratings yet
ID Partner Network Transformation
52 pages
01Module15-230110-190214
PDF
No ratings yet
01Module15-230110-190214
48 pages
Inspection Deployment Models With AWS Network Firewall Ra
PDF
No ratings yet
Inspection Deployment Models With AWS Network Firewall Ra
7 pages
Developing_a_Resilient_Application_with_AWS_Cloud_Services
PDF
No ratings yet
Developing_a_Resilient_Application_with_AWS_Cloud_Services
10 pages
AWS Advanced Networking - Specialty Sample Exam Questions
PDF
No ratings yet
AWS Advanced Networking - Specialty Sample Exam Questions
4 pages
Site-to-Site VPN
PDF
No ratings yet
Site-to-Site VPN
22 pages
AWS FAT Module 3
PDF
No ratings yet
AWS FAT Module 3
7 pages
How Do I Build A Global Transit Network On AWS?
PDF
No ratings yet
How Do I Build A Global Transit Network On AWS?
3 pages
VPC Section
PDF
No ratings yet
VPC Section
21 pages
Aws VPC
PDF
No ratings yet
Aws VPC
75 pages
Module 2 - Networking on AWS -Animated
PDF
No ratings yet
Module 2 - Networking on AWS -Animated
36 pages
AWS Networking
PDF
No ratings yet
AWS Networking
5 pages
Amazon-VPC Basics-DeepDive-1
PDF
No ratings yet
Amazon-VPC Basics-DeepDive-1
13 pages
VPC-
PDF
No ratings yet
VPC-
27 pages
AWS Network
PDF
No ratings yet
AWS Network
20 pages
Aw Stech Essentials
PDF
No ratings yet
Aw Stech Essentials
72 pages
Amazon AWS Certified Advanced Networking
PDF
No ratings yet
Amazon AWS Certified Advanced Networking
21 pages
VPC Peering
PDF
No ratings yet
VPC Peering
17 pages
Ch5 Networking
PDF
No ratings yet
Ch5 Networking
3 pages
AWS Networking Terms- DevopsRitiks
PDF
No ratings yet
AWS Networking Terms- DevopsRitiks
6 pages
VPC
PDF
No ratings yet
VPC
5 pages
Virtual Private Cloud (VPC) : Data Center
PDF
No ratings yet
Virtual Private Cloud (VPC) : Data Center
12 pages
Virtual Networks Unlocked: Your Guide to Azure Connectivity
From Everand
Virtual Networks Unlocked: Your Guide to Azure Connectivity
Kameron Hussain
No ratings yet
Bit-Torrent in Erlang
PDF
No ratings yet
Bit-Torrent in Erlang
75 pages
Kubernetes Commands Cheat Sheet 1713575425
PDF
No ratings yet
Kubernetes Commands Cheat Sheet 1713575425
6 pages
Kertas Kerja AMC
PDF
No ratings yet
Kertas Kerja AMC
5 pages
Bug New All
PDF
No ratings yet
Bug New All
6 pages
FALLSEM2024-25 SWE4005 ETH VL2024250103359 2024-07-26 Reference-Material-I
PDF
No ratings yet
FALLSEM2024-25 SWE4005 ETH VL2024250103359 2024-07-26 Reference-Material-I
56 pages
Notes PDC
PDF
No ratings yet
Notes PDC
6 pages
Microsoft Cloud Networking For Enterprise Architects
PDF
No ratings yet
Microsoft Cloud Networking For Enterprise Architects
12 pages
Serverless Computing For IoT
PDF
No ratings yet
Serverless Computing For IoT
12 pages
Best Practices For Running Oracle Siebel CRM On Aws
PDF
No ratings yet
Best Practices For Running Oracle Siebel CRM On Aws
31 pages
AWS Capstone Options
PDF
No ratings yet
AWS Capstone Options
3 pages
Week-1 - Lecture Notes of NPTEL
PDF
No ratings yet
Week-1 - Lecture Notes of NPTEL
126 pages
Oracle Flex Cluster 12c
PDF
No ratings yet
Oracle Flex Cluster 12c
8 pages
DevOpsCV 1
PDF
No ratings yet
DevOpsCV 1
3 pages
Cloud Computing 2023
PDF
No ratings yet
Cloud Computing 2023
26 pages
arif2019
PDF
No ratings yet
arif2019
4 pages
AZ-900 Study Guide-3
PDF
No ratings yet
AZ-900 Study Guide-3
14 pages
Web Services
PDF
No ratings yet
Web Services
35 pages
Intro Haddop Ecosystem 24sep2020
PDF
No ratings yet
Intro Haddop Ecosystem 24sep2020
127 pages
SumatraPDF Settings
PDF
No ratings yet
SumatraPDF Settings
36 pages
Glusterfs Presentation PDF
PDF
No ratings yet
Glusterfs Presentation PDF
20 pages
BDA - Chapter-1-Components of Hadoop Ecosystem - Lecture 3
PDF
0% (1)
BDA - Chapter-1-Components of Hadoop Ecosystem - Lecture 3
38 pages
Answer: C
PDF
No ratings yet
Answer: C
24 pages
Building Web Services With Abap and Sap Web Application Server
PDF
No ratings yet
Building Web Services With Abap and Sap Web Application Server
0 pages
Introduction To UEC and Its Components: 1.1 Cloud
PDF
No ratings yet
Introduction To UEC and Its Components: 1.1 Cloud
10 pages
Veritas NetBackup v10 Advanced Administration
PDF
No ratings yet
Veritas NetBackup v10 Advanced Administration
5 pages
Codigo Tipo de Movimiento Tipo de Captura Transaccion
PDF
No ratings yet
Codigo Tipo de Movimiento Tipo de Captura Transaccion
48 pages
Peserta PRO DTS-CKO REDHAT ?
PDF
No ratings yet
Peserta PRO DTS-CKO REDHAT ?
17 pages
Azure Arc Data Services Architecture
PDF
No ratings yet
Azure Arc Data Services Architecture
35 pages